Get started
Authentication
The two services you call, their base URLs, and the tokens each one takes.
Services and base URLs#
There are two services you talk to:
| Service | Used for | Base URL |
|---|---|---|
| Events collector | Sending events, from the browser or your servers | https://<collector-host>/v1 |
| Control plane | Configuration (event types, metrics, segments) and reads (profiles, members) | https://api.breeze.in/cdp/control-plane |
Set your own base URLs, tenant and workspace on Your values, and every example on the site uses them.
Collector authentication#
| Events | Endpoint | Token | Identifiers accepted |
|---|---|---|---|
| Server-side | /events/authenticated | Authorization: Bearer $COLLECTOR_TOKEN | All, including email and phone. These events are trusted and can link identities. |
| Browser | /events | None | Device-level only (cookie, device_id), because anyone can call it. |
Control-plane tokens#
Every request carries Authorization: Bearer <token>. There are two kinds of token:
| Token | Format | Who has it | Can do |
|---|---|---|---|
| Tenant | cpt_<id>.<secret> | Your platform or admin service (issued by the BreezeIQ team) | Everything in the tenant: configuration writes, all workspaces, minting workspace tokens |
| Workspace | cpw_<id>.<secret> | Dashboards and apps of one workspace | Read-only: that workspace's profiles, segments and members, plus the tenant's event types and metric definitions |
A token can never see another tenant's data, and a workspace token can never see another workspace's data (403). Mint workspace tokens with the Tokens API.
Check a token#
GET /v1/whoami tenant or workspace token
Returns what the token is for.
curl "https://api.breeze.in/cdp/control-plane/v1/whoami" -H "Authorization: Bearer $BREEZEIQ_TOKEN"{
"scope": "workspace",
"tenant_id": "breeze",
"workspace_id": "my-store"
}{
"scope": "tenant",
"tenant_id": "breeze"
}Keep tokens in environment variables
Use environment variables (export BREEZEIQ_TOKEN=...) rather than pasting tokens into scripts or tickets. Every example here uses them that way.